How to use VeilVoice

A walkthrough: anonymise a file, scramble a microphone, verify a download.

This section is also part of the front page, where it sits in context with the rest.

There are two programs in the archive: veilvoice-gui, the desktop app, and veilvoice, the command line. They share one engine, so anything one can do the other can. Nothing installs a service, writes to a registry, or phones home. Delete the folder and it is gone.

  1. Give it a recording

    wav, mp3, flac, ogg, m4a and friends. Open the desktop app on the anonymise file tab and choose one, or point the command line at it. Roughly 90× faster than real time, so an hour of audio takes well under a minute.

    veilvoice anonymise interview.mp3 -o clean.wav
  2. The voiceprint is destroyed, the words are kept

    Each frame's measured phase is thrown away and resynthesised, and pitch register, vocal-tract length and spectral tilt are each collapsed onto one canonical value, so a whole population of speakers lands on the same output and there is nothing left to invert. What comes out is understandable, transcribable, and belongs to nobody.

    The same energy, and no shared structure. Left, a voice as it was recorded; right, what is left after the phase relationship that identified the speaker has been destroyed. The words survive the journey; the speaker does not.

  3. It is encrypted before it reaches the disk

    The result is sealed into a .veil container as it is written, so -o clean.wav produces clean.wav.veil. The WAV is built in memory and encrypted there, so the plaintext never exists on disk, not even for a moment, because a file that is written and then deleted cannot be reliably taken back on flash storage.

    veilvoice decrypt clean.wav.veil -o clean.wav   # when you want it back
  4. Or scramble your microphone as you speak

    The Studio tab routes your veiled voice into a virtual audio cable. Every application on the machine, whether a call, a stream or a recorder, then receives that instead of you, with no per-app setup. The same tab keeps a take of it, sealed into a vault, when you ask for one.

  5. Check nothing else is listening

    De-identifying your voice on a call achieves little if a second program is recording the raw microphone at the same time. The monitor tab names what is holding your microphone and camera and warns the moment something starts.

  6. Lock the app behind you

    Set a password on the lock tab and VeilVoice will not open without it. The lock button in the header locks it immediately and clears the session passphrase with it.

The two passwords, and why there are two

The app lock

Decides whether VeilVoice opens at all. Argon2id verifier, rate limited, three attempts free and then a doubling wait.

The recording passphrase

Encrypts the files it writes. Argon2id at 256 MiB, or seal to a post-quantum hybrid public key instead.

They are deliberately different secrets. If one password did both, then opening the app would be the same act as unsealing everything it had ever written, which is the opposite of what a lock is for. VeilVoice keeps the two derivations domain-separated, so typing the same passphrase in both places still does not produce two copies of one value. Use two anyway: one guess that opens both defeats the point regardless of the maths.

The app lock is not tamper-proof, and cannot be. A program running on your computer has nowhere to hide a secret from that computer: anyone who can write to your files can delete the lock, and anyone holding the disk can attack the stored password hash offline. It protects against casual access, meaning the person who sits down at your unlocked session, which is a real and common threat, and is exactly what the unlock screen says it is for. If someone taking your disk is the threat, encrypt the whole volume.